« Volver al listado

CVE-2018-10630

Estado: ModificadaCrítica (9.8)—

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-10630",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "ICS-CERT",
          "product": "Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001",
          "versions": [
            {
              "status": "affected",
              "version": "Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-08-10T19:29:00.240",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/105051",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-221-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/105051",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-221-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open."
    },
    {
      "lang": "es",
      "value": "Para las versiones anteriores a la 2.001.0037.001 de Crestron TSW-X60 y las versiones anteriores a la 1.502.0047.001 de MC3, los dispositivos se distribuyen con la autenticación deshabilitada y no existen indicaciones de que los usuarios deban tomar medidas para habilitada. Al estar comprometidos, el acceso a la consola CTP se deja abierto."
    }
  ],
  "lastModified": "2026-06-17T01:34:18.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:crestron:tsw-x60_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0C26C6C-4F6D-4084-AA36-CDBBF5B182F0",
              "versionEndExcluding": "2.001.0037.001"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:crestron:tsw-1060-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B827C62-5712-4511-8506-74B925DA053B"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-1060-nc-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D41EF7B1-8F7A-4F66-B9B1-90405F507FE8"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-1060-nc-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "28A41D87-44CE-452D-A696-5DFCAEFF3D4C"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-1060-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BCAC6D4C-51C5-4687-B9F5-8B3FD9F4503E"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-560-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A7B4BBE9-C4D1-42C1-AD23-3F47D2E7BCD4"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-560-nc-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "621667FD-7FC9-4606-857B-2423EAEF613A"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-560-nc-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "30C58417-CA62-4E68-8421-A968406F4797"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-560-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5A888FB2-6F71-4D45-9E03-505DAD49909A"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-760-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "01970CD6-3FE7-42BF-A2BB-358692F8B787"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-760-nc-b-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "507A0431-6EB0-4535-AD17-97C09542AB6E"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-760-nc-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B084CEC7-E1B0-44F1-AAAB-CEC86EA767AF"
            },
            {
              "criteria": "cpe:2.3:h:crestron:tsw-760-w-s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5FBE392B-4A2B-4B7E-9F1D-6E55FCE0146C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:crestron:mc3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B16FD3DA-6249-4252-A76A-E3BDDD37E849",
              "versionEndExcluding": "1.502.0047.001"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:crestron:mc3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3E648452-F573-478D-9A32-1D76534926D4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}